THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Ed Moore, Sr. Director of Identity and Access Management, Carnival CorporationHow many times have you looked at your data and found it hard to find the needle in the hay stack? Smaller sets are data are easier to find the data anomalies or outliers. This is because that you have the smaller hay stack or sample sizes and things tend to stick out more easily and be pick out often.
When you increase both your sample size or the number of rows in that given table and you also increase the length of that table, then it becomes much harder to find out exactly where to start. Sure, you can run queries but some things do not stand out to you. You can also use filters. However, if you want to make sure that you are quickly seeing and addressing your outliers, then you want to put that data into a data visualization tool.
Identity and Access Management is no different. We as security practitioners need to be able to come up with a model and then train that model on our own data so to speak. We need to drop things into our tool and not look at the similarities, but check out the differences. These are the areas that you need to look at and take action.
In active directory for example, you need to see trends of when you are getting more failed logins and from what location or country. If you are getting thousands of failed logins and you only have a few people in your company from that state or country, then you know that you need to block that country. This could mean that someone is trying to do your instance harm. Block first and then do your research. How can I block something like that you may be asking. Well, if you are using Azure, then you can use a Conditional Access policy to block countries that you do not want these countries originating in. Yes, there are ways around this, but it is a start.
“We as security practitioners need to be able to come up with a model and then train that model on our own data so to speak.”
Data quality is something else that you will get data visualization. You will see what is the issue and correct it at the source or find out who is altering your data.
Come out with a list of those items that you wanted to use as your key risk or key performance indicators for IAM. It should not just be what are the number of successful logins for example. Yes, that metric is important but there are others out there and you and your team need to be able to look at the data in a monthly or weekly timeframe and then be able to fix your issues that you see in the data. Once you have that down and you are seeing fewer outliers, then adjust your timeframe to daily so that you can catch things faster.
Remember crawl, walk, run when starting out on anything new. This is a trial-and-error process. Microsoft has tools like Power BI where you and drop your data into that production and then set up dashboards with drill through capability so that you can see the low-level details.
Identity Access Governance has started to build in features just like this for data visualization purposes. SailPoint now has Access Insights module that comes with Data Explorer. This tool allows for you to build dashboards on your data inside of SailPoint.
How do you get started? Start with an extract of data from one of your systems. Once you have the extract, then you will need to pull that into Power BI, or something similar. You are then just looking at the data that you have and trying to see what are some of the outliers that you see already. Start to ask yourself questions in your data and find out the results.
Start with type of accounts. Are any type attributes blank for example? Is anything misspelled? Should test accounts be a type of account?
Here are some other questions that you may want to ask of your data:
● What is the last time that people changed their password by account type?
● Are there any accounts out there where the password is not required?
● How many accounts has someone changed to password never expire by type?
● Number of accounts suspended in the past 180 days due to inactivity by type?
● Number of accounts purged in the past 180 days due to inactivity by type?
● Number of accounts locked in the past 10 days?
● Number of accounts locked multiple times in the past 10 days?
● Location of all logins in the past 30 days?
● Number of password resets for accounts with account creation less than 15 business days?
● Number of accounts scanned but not vaulted in your PAM solution?
● Last time accounts were checked out of PAM solution?
● Last time that accounts were logged into by account type?
These are some of the questions that you may have answers for above. However, it is also important to show the trend over time. You need to see if you are improving or getting worse. If you can see it and you know about it, then it can be managed. You can also use this information by department and have like a scoreboard for each of the teams and give them a score.
The most important thing for you and your team to do is to start. This is something that you have to do and work with for it to make sense to you and your team. The first time through will take you the most time to define what you want to ask about your data. The more and more that you drill down and look at everything visually, then the better your IAM solution and offering will be moving forward. Good luck on finding all of your needles in that hay stack and improving your IAM solution.